🎄 Join our Annual Holiday wargame and win prizes!


Cross Frame Scripting

Cross Frame Scripting (XFS) hides a legitimate website in an iframe. User unknowingly interacts with the iframe white interacting with the UI from another domain.

Remediation

Configure Content Security Policy and disallow framing.

Metadata

  • Severity: low
  • Slug: cross-frame-scripting

CWEs

  • 1021: Improper Restriction of Rendered UI Layers or Frames

OWASP

  • A05:2021: Security Misconfiguration

Available Labs

Select a language to explore available labs for this vulnerability.

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more